论文标题
没有任何通过:基于区块链的联合身份管理系统
None Shall Pass: A blockchain-based federated identity management system
论文作者
论文摘要
用户身份的身份验证和授权通常由服务提供商或身份提供商完成。但是,这些集中式系统限制了用户对自己身份的控制,并且由于其集中性质而容易出现大规模数据泄漏。我们提出了一个基于区块链的身份管理系统,以使用基于属性的访问控制策略和隐私保护算法对用户进行身份验证和授权,并最终将用户身份的控制返回给用户。 我们提出的系统将使用私人区块链,该区块链将以安全,可验证的方式存储重新认证事件以及数据访问和授权请求,从而确保数据的完整性。本文提出了一种机制,以任何政府当局或其他当局以不可变和安全的方式发行的文件,例如护照,驾驶执照,电费等。数据所有者负责使用OpenID Connect协议在需要时对用户的身份进行身份验证和传播。我们使用先进的加密算法为用户提供假名,从而确保其隐私。这些算法还确保在需要时确保交易的可唤起性。我们提出的系统有助于减轻最近隐私辩论中的一些问题。该项目在公民转移,国际服务天意,银行,所有权转让等中找到其申请。通用框架也可以扩展到银行,医院等财团。
Authentication and authorization of a user's identity are generally done by the service providers or identity providers. However, these centralized systems limit the user's control of their own identity and are prone to massive data leaks due to their centralized nature. We propose a blockchain-based identity management system to authenticate and authorize users using attribute-based access control policies and privacy-preserving algorithms and finally returning the control of a user's identity to the user. Our proposed system would use a private blockchain, which would store the re-certification events and data access and authorization requests for users' identities in a secure, verifiable manner, thus ensuring the integrity of the data. This paper suggests a mechanism to digitize documents such as passports, driving licenses, electricity bills, etc., issued by any government authority or other authority in an immutable and secure manner. The data owners are responsible for authenticating and propagating the users' identities as and when needed using the OpenID Connect protocol to enable single sign-on. We use advanced cryptographic algorithms to provide pseudonyms to the users, thus ensuring their privacy. These algorithms also ensure the auditability of transactions as and when required. Our proposed system helps in mitigating some of the issues in the recent privacy debates. The project finds its applications in citizen transfers, inter-country service providence, banks, ownership transfer, etc. The generic framework can also be extended to a consortium of banks, hospitals, etc.